- Protected password entered
Account condition enforcement triggered
App banner
Blocked URL visited
Browser extension blocked or enabled
Clipboard blocking
Cloned login page detected
Custom detection
Domain category blocking triggered
File download blocking
File upload blocking
Malicious browser extension detected
Malicious copy and paste detected
MFA enforcement event
Password logging prevention
Phishing tool detected
Stolen credentials detected
Strong password enforcement event
SSO password used
Protected password entere...
Security
X-Signature
A protected password entered event occurred.
The unique identifier for the event. This can be used as an idempotency key.
Example:"c478966c-f927-411c-b919-179832d3d50c"
The unique identifier of the tenant the event belongs to.
Example:"4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a"
When the event occurred, formatted as a UNIX timestamp (in seconds).
Example:1698604061
The description of the event. Note: this is subject to change and should not be used to match on this object.
Example:"user@example.com entered their Microsoft 365 password into a different URL, but was blocked"
The friendly name of this object. Note: this is subject to change and should not be used to match on this object.
Example:"Protected password entered"
- https://api.pushsecurity.comhttps://api.pushsecurity.com/protected-password-entered
{ "version": "1", "id": "c478966c-f927-411c-b919-179832d3d50c", "tenantId": "4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a", "timestamp": 1698604061, "category": "CONTROL", "description": "user@example.com entered their Microsoft 365 password into a different URL, but was blocked", "object": "PROTECTED_PASSWORD_ENTERED", "friendlyName": "Protected password entered", "new": { "employee": { "id": "2a2197de-ad2c-47e4-8dcb-fb0f04cf83e0", "email": "john.hill@example.com", "firstName": "John", "lastName": "Hill", "department": "Security Engineering", "location": "New York", "licensed": true, "chatopsEnabled": true, "creationTimestamp": 1698669223 }, "mode": "BLOCK", "action": "DISPLAYED", "url": "https://evil.com/okta.php", "referrerUrl": "https://statics.teams.cdn.office.net/", "email": "john.hill@example.com", "appType": "OKTA", "sourceIpAddress": "8.158.25.38", "browser": "CHROME", "os": "MACOS", "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 Edge/16.16299" } }